The ‘Madi’ infostealers – a detailed analysis - Securelist
ID: 89dc065d-7ea2-4fb4-b3c7-132ff14a0d1d
STIX ID: report--89dc065d-7ea2-4fb4-b3c7-132ff14a0d1d
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2014-07-15
Last Modified Date: 2014-07-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a detailed reverse-engineering analysis of the Madi infostealer campaign: how downloaders install the infostealer, the Delphi-based malware structure (52 timers), keylogger and screen/audio capture capabilities, file-collection and exfiltration workflows (Base64, Sendfilejj.html/sik.php), C2 check-in and command retrieval (dastor/dast.xls, ReReReRe.htm/SeSeSeSe.htm), and numerous filenames/markers used for control and exfiltration (e.g., nam.dll, poki65.pik, *.BMH, *.KILOP, tamamshodfile). Despite sloppy coding, the campaign was effective with ~800 victims and multiple active data-stealing primitives.
